Platform compatibility
When to use
- The app is available on the Mac App Store or iOS App Store
- You want Apple to manage installer updates automatically
- You need to deploy apps to supervised iOS/iPadOS devices
Prerequisites
- An Apple Business Manager (ABM) account
- VPP connected to the dashboard
Connect Apple Volume Purchase Program (VPP)
1
Generate a VPP token in ABM
- In ABM, go to Sites and create a site if you don’t have one.
- Generate a VPP token from that site and download it.
2
Import the token
- Go to MDM > Software > Add app > App Store (VPP).
- Select the “No Team” scope.
- Upload the VPP token file.
3
Add licenses in ABM
Before deploying an app, ensure you have enough licenses:
- In ABM, go to Apps and Books.
- Search for the app and purchase the required number of licenses.
- Assign the licenses to the site linked to your VPP token.
- A content token is valid for one year after it is created.
- It becomes invalid if the password of the Managed Apple Account that created it is changed.
- Recommendation: create a dedicated Managed Apple Account with a custom role limited to the “Assign licenses for Apps and Books” permission, so token validity does not depend on an individual’s password changes or departure.
Migrate VPP from another MDM
Follow this order — Apple requires the content token to be removed from your previous MDM before it’s uploaded anywhere else.1
Remove the content token from your previous MDM
This is done by your previous provider or in their console. Apple requires the token to be removed there before it’s uploaded to Primo.
2
Download a fresh content token in Apple Business
Go to Settings > Payments & Billing > Apps and Books > Download.
3
Upload the token to Primo
Follow the Import the token step above.
4
Reassign any apps that come back unassigned
Some apps may need to be manually reassigned to devices after the new token is active.
Apps already installed on devices stay usable for up to 30 days after the old token is removed, or until the app developer performs a receipt check. Don’t spread the migration over a longer window.
Available options
- Install automatically — the app is silently pushed to all targeted devices (macOS, iOS, iPadOS).
- Self-service — the app appears in the Self-Service portal for employees to install on demand (macOS, iOS, iPadOS).
- Install during Zero Touch — the app is pre-installed during device provisioning (macOS only).
How employees open the Self-Service portal depends on the platform.
- macOS — from the Fleet Desktop icon in the menu bar.
- iOS / iPadOS — from the portal’s web URL. Add it to the Home Screen with the Web Clips control and its Add the Self-Service web clip option.
How to add
- Go to MDM > Software and click Add app.
- Select App Store (VPP) and choose the platform (macOS or iOS/iPadOS).
- Browse or search for the app.
- Configure deployment options.
- Click Add software.